Threat Bus Logo

Threat Bus

0
Free
Visit Website

A threat intelligence dissemination layer for open-source security tools. Threat Bus is a pub-sub broker for threat intelligence data, allowing seamless integration of threat intel platforms like OpenCTI or MISP with detection tools like Zeek or VAST. It transports indicators and sightings in STIX-2 format, features a plugin-based architecture for easy extension, and offers snapshotting for requesting threat intelligence data for specific time ranges.

FEATURES

ALTERNATIVES

A tool for creating custom detection rules from YAML input

A tool designed to extract additional value from enterprise-wide AppCompat / AmCache data

In-depth analysis of real-world attacks and threat tactics

A Python library for handling TAXII v1.x Messages and invoking TAXII Services.

Platform for the latest threat intelligence information

A tool for quick and effective Yara rule creation to isolate malware families and malicious objects.

A collection of APT and cybercriminals campaigns with various resources and references.

Cisco Umbrella is a cloud security platform that offers protection against threats on the internet by blocking malicious activity.

PINNED